T The Triage ManualTechnical Guides for IT Emergencies
P1 · Remote Access & VPN

VPN not connecting for remote workers

Remote staff can't connect. Vendor-neutral diagnostic flow: certificate → authentication → routing → policy → licence → client.

Indicators

Likely causes

Diagnostic steps

  1. Test connectivity to the gateway public IP on the VPN port (TCP 443 SSL VPN, UDP 500/4500 IKEv2). If unreachable from outside, ISP / firewall / port issue first
  2. Check certificate: expiry, chain, and SAN matching the FQDN clients use
  3. Authentication: test against the IdP backend separately (RADIUS test from CLI, or SAML trace via Fiddler)
  4. Inspect tunnel state on gateway: get vpn ipsec tunnel summary (Fortinet), show vpn-sessiondb (Cisco), event log (SonicWall)
  5. If tunnel up but no traffic: confirm pushed routes, check policy / firewall rules from VPN zone to internal
  6. Verify firewall licence active (UTM/SSL VPN often gated)

Resolution path

Prevention

Tools

References

vpnfirewallfortinetsonicwallmerakiciscocertificate